From 7dd967b9594af740f73c5aa8b3a3c5ceb7acc2f2 Mon Sep 17 00:00:00 2001 From: Phil Leggetter Date: Thu, 1 Oct 2026 10:11:41 +0100 Subject: [PATCH] Correct what a Hookdeck credential is MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit The harness comment said "one credential type, two projects". The first half is wrong. Hookdeck has organization API keys as well as project API keys, and the Outpost API additionally accepts a short-lived tenant JWT from `GET /tenants/{tenant_id}/token` — `docs/apis/openapi.yaml` in hookdeck/outpost carries both `AdminApiKey` and `TenantJwt`, and the tenant portal uses the second for browser calls. Caught in review of hookdeck/agent-skills#28, which had taken the claim from #40 and restated it in a skill agents read. A wrong sentence in this repository became a wrong sentence in a product artefact, which is the propagation path worth noticing: we write the findings, so our errors ship. What is true of this harness is narrower and is what the comment now says: it injects one project API key per project, and which project a key belongs to decides whether an Outpost call works. Co-Authored-By: Claude Opus 5 Claude-Session: https://claude.ai/code/session_01MQzUoMAwEBJWpEGVvVzSjK --- packages/hookdeck/src/runtime.ts | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/packages/hookdeck/src/runtime.ts b/packages/hookdeck/src/runtime.ts index d4d7a02..9c0c1db 100644 --- a/packages/hookdeck/src/runtime.ts +++ b/packages/hookdeck/src/runtime.ts @@ -141,11 +141,20 @@ export function hookdeckRuntime(options: HookdeckRuntimeOptions): EvalRuntime { // variable, so the skills delta could not be separated from // credential disclosure — the run measured our own omission. // - // One credential type, two projects. Both keys authenticate + // Two project API keys, one per project. Both authenticate // `api.hookdeck.com` and the CLI; only the Outpost project's key // reaches the Outpost subdomain, and a key from another project // gets a `404` there rather than anything that says why (#39). // + // This said "one credential type" until 1 October, which is wrong + // and had propagated: Hookdeck has organization API keys as well as + // project API keys, and the Outpost API additionally accepts a + // short-lived tenant JWT from `GET /tenants/{tenant_id}/token` + // (`docs/apis/openapi.yaml` carries both `AdminApiKey` and + // `TenantJwt`). What is true of *this harness* is narrower: it + // injects one project API key per project, and which project a key + // belongs to is what decides whether an Outpost call works. + // // The wording points at the API rather than the CLI deliberately, // and that is a statement about the pinned version rather than a // permanent one. Against `HOOKDECK_CLI_VERSION` 2.5.0 the Outpost